Your third party has a third party

Concentration risk is usually discovered during an event, when three apparently independent contingency arrangements turn out to route through one regional facility or one cloud availability zone. The mapping exercise that would have surfaced it is unglamorous and takes a few weeks.

How to do the mapping

Start with the services your organization has already ranked highest — if that ranking does not exist yet, that is the prior problem to solve. Trace each one down two levels rather than one. Not just who you contract with, but who they rely on to deliver the part you actually depend on.

Two levels is usually enough. The point is not a complete supply-chain graph; it is finding the places where apparent redundancy collapses into a single point.

The findings tend to be uncomfortable and immediately actionable, which is a good combination.

What to do with the answer

Some concentrations are worth accepting. Others are worth paying to remove. The value of the exercise is that the choice becomes explicit and lands in front of the people who can fund it, rather than being discovered by an incident commander at two in the morning.

Previous
Previous

Impact tolerances are a business decision, not a technical one

Next
Next

The after-action report nobody reads